Trivision · Trivision Camera Nc227Wf · CVE-2025-1739
**Name of the Vulnerable Software and Affected Versions**
Trivision Camera NC227WF version 5.8.0
**Description**
An Authentication Bypass issue allows an attacker to retrieve administrator's credentials in cleartext. This is achieved by sending a request to the "/en/player/activex pal.asp" API endpoint with random credentials, resulting in successful authentication of the application.
**Recommendations**
For Trivision Camera NC227WF version 5.8.0, as a temporary workaround, consider restricting access to the "/en/player/activex pal.asp" API endpoint until a patch is available.